Compare commits

..

No commits in common. "main" and "buildah" have entirely different histories.

9 changed files with 78 additions and 171 deletions

View file

@ -1,43 +0,0 @@
name: Clean up Forgejo Container Registry
on:
schedule:
- cron: '0 0 * * 0' # Runs every Sunday at midnight
workflow_dispatch: # Allows manual triggering
jobs:
delete-old-images:
runs-on: almalinux-10
steps:
- name: Delete old versions
run: |
REGISTRY="forge.pc-rytteren.dk"
OWNER="${{ github.repository_owner }}"
IMAGE="my-ostree-os"
MIN_KEEP=50
TOKEN="${{ secrets.PACKAGE_TOKEN }}"
# Fetch all container packages with this name, sorted oldest first (by id)
# API returns a list of package objects, each with "id" and "version"
RAW=$(curl -s -H "Authorization: token ${TOKEN}" \
"https://${REGISTRY}/api/v1/packages/${OWNER}?type=container&q=${IMAGE}&limit=200")
# Filter only packages with the correct name and extract id, sort oldest first
IDS=$(echo "$RAW" | tr '{' '\n' | grep "\"name\":\"${IMAGE}\"" | \
sed 's/.*"id":\([0-9]*\).*/\1/' | sort -n)
TOTAL=$(echo "$IDS" | grep -c '[0-9]' || true)
echo "Found ${TOTAL} packages total, keeping ${MIN_KEEP}"
if [ "$TOTAL" -le "$MIN_KEEP" ]; then
echo "No packages to delete"
exit 0
fi
# Delete the oldest (lowest ids) beyond MIN_KEEP
TO_DELETE=$(echo "$IDS" | head -n $(( TOTAL - MIN_KEEP )))
for ID in $TO_DELETE; do
echo "Deleting package id: ${ID}"
curl -s -X DELETE -H "Authorization: token ${TOKEN}" \
"https://${REGISTRY}/api/v1/packages/${OWNER}/${ID}"
done

View file

@ -24,6 +24,7 @@ jobs:
permissions: permissions:
contents: read contents: read
packages: write packages: write
id-token: write # Påkrævet til cosign keyless signering
steps: steps:
@ -43,7 +44,6 @@ jobs:
tags: | tags: |
type=ref,event=branch type=ref,event=branch
type=raw,value=latest,enable={{is_default_branch}} type=raw,value=latest,enable={{is_default_branch}}
type=raw,value=${{ github.ref_name }}
type=raw,value=${{ github.ref_name }}-10 type=raw,value=${{ github.ref_name }}-10
type=raw,value=${{ github.ref_name }}-10.${{ steps.date.outputs.date }} type=raw,value=${{ github.ref_name }}-10.${{ steps.date.outputs.date }}
@ -57,9 +57,13 @@ jobs:
run: | run: |
# Vi bygger med 'raw-img' lokalt # Vi bygger med 'raw-img' lokalt
buildah bud \ buildah bud \
--label "org.opencontainers.image.source=https://pc-rytteren.dk/forge/${{ github.repository }}" \ --label "org.opencontainers.image.source=https://forge.pc-rytteren.dk/${{ github.repository }}" \
-t raw-img . -t raw-img .
# Gem det primære tag til signering (vi tager det første fra listen)
PRIMARY_TAG=$(echo "${{ steps.meta.outputs.tags }}" | head -n 1)
echo "primary_tag=$PRIMARY_TAG" >> $FORGEJO_OUTPUT
- name: Push to Forgejo Container Registry - name: Push to Forgejo Container Registry
if: github.event_name != 'pull_request' if: github.event_name != 'pull_request'
run: | run: |
@ -69,3 +73,18 @@ jobs:
buildah push "$tag" buildah push "$tag"
done done
- name: Install cosign
if: github.event_name != 'pull_request'
uses: sigstore/cosign-installer@v3.3.0
- name: Log into Forgejo Container Registry (Cosign)
if: github.event_name != 'pull_request'
run: |
cosign login ${{ env.REGISTRY }} -u ${{ github.actor }} -p ${{ secrets.PACKAGE_TOKEN }}
- name: Sign image
if: github.event_name != 'pull_request'
run: |
# Vi signerer det primære tag.
# Vi bruger --yes til at acceptere betingelserne automatisk.
cosign sign --yes "${{ steps.build-image.outputs.primary_tag }}"

21
.github/workflows/cleanup.yml vendored Normal file
View file

@ -0,0 +1,21 @@
name: Ryd op i GHCR
on:
schedule:
- cron: '0 0 * * 0' # Kører hver søndag ved midnat
workflow_dispatch: # Gør det muligt at køre den manuelt
jobs:
delete-old-images:
runs-on: ubuntu-latest
permissions:
packages: write
steps:
- name: Slet gamle versioner
uses: actions/delete-package-versions@v5
with:
package-name: 'my-ostree-os' # Skift til dit image navn
package-type: 'container'
min-versions-to-keep: 50
delete-only-untagged-versions: 'false'
token: ${{ secrets.GITHUB_TOKEN }}

View file

@ -3,9 +3,7 @@ FROM quay.io/almalinuxorg/atomic-desktop-kde:10
ARG KERNEL=kernel-cachyos ARG KERNEL=kernel-cachyos
ENV KERNEL=${KERNEL} ENV KERNEL=${KERNEL}
RUN rpm -e --nodeps gpsd-libs RUN echo 'omit_drivers+=" nouveau "' | tee /etc/dracut.conf.d/blacklist-nouveau.conf
RUN dnf upgrade -y
COPY bin/set_next_version.sh /tmp COPY bin/set_next_version.sh /tmp
RUN /tmp/set_next_version.sh RUN /tmp/set_next_version.sh
@ -15,49 +13,31 @@ RUN dnf config-manager --add-repo=https://negativo17.org/repos/epel-nvidia.repo
RUN dnf install --nogpgcheck -y https://mirrors.rpmfusion.org/free/el/rpmfusion-free-release-$(rpm -E %rhel).noarch.rpm https://mirrors.rpmfusion.org/nonfree/el/rpmfusion-nonfree-release-$(rpm -E %rhel).noarch.rpm RUN dnf install --nogpgcheck -y https://mirrors.rpmfusion.org/free/el/rpmfusion-free-release-$(rpm -E %rhel).noarch.rpm https://mirrors.rpmfusion.org/nonfree/el/rpmfusion-nonfree-release-$(rpm -E %rhel).noarch.rpm
RUN dnf config-manager --add-repo https://copr.fedorainfracloud.org/coprs/g/SonicDE/SonicDE-EL10/repo/rhel+epel-10/group_SonicDE-SonicDE-EL10-rhel+epel-10.repo -y RUN dnf config-manager --add-repo https://copr.fedorainfracloud.org/coprs/andersrh/sonicDE/repo/rhel+epel-10/andersrh-sonicDE-rhel+epel-10.repo -y
RUN dnf config-manager --add-repo https://copr.fedorainfracloud.org/coprs/g/xlibre/xlibre-xserver/repo/rhel+epel-10/group_xlibre-xlibre-xserver-rhel+epel-10.repo -y RUN dnf config-manager --add-repo https://copr.fedorainfracloud.org/coprs/g/xlibre/xlibre-xserver/repo/rhel+epel-10/group_xlibre-xlibre-xserver-rhel+epel-10.repo -y
# This may be necessary for the speakers and internal microphone # This may be necessary for the speakers and internal microphone
RUN dnf install -y alsa-sof-firmware RUN dnf install -y alsa-sof-firmware
RUN dnf install xorg-x11-xinit xkbcomp xinput xlibre-xserver-Xorg xlibre-xserver-common xlibre-xf86-input-libinput cage weston redshift xrandr -y RUN dnf install sonic-workspace-x11 sonic-win sonic-interface-libraries sonic-workspace --allowerasing -y
RUN dnf install --allowerasing -y \
sonic-workspace \
sonic-workspace-libs \
sonic-workspace-common \
sonic-workspace-x11 \
sonic-win \
sonic-desktop-interface \
sonic-interface-libraries
RUN dnf install --allowerasing -y sonic-keybind-daemon sonic-frameworks-windowsystem sonic-system-info sonic-screen sonic-screen-library sonic-sysguard-library
RUN dnf remove -y sddm && \
dnf install --allowerasing -y sonic-login-manager
RUN dnf install -y fish distrobox nvtop intel-media-driver libva-intel-driver htop RUN dnf install -y fish distrobox nvtop intel-media-driver libva-intel-driver htop
RUN dnf install -y https://github.com/TheAssassin/AppImageLauncher/releases/download/v3.0.0-beta-3/appimagelauncher_3.0.0-beta-2-gha287.96cb937_x86_64.rpm RUN dnf install -y https://github.com/TheAssassin/AppImageLauncher/releases/download/v2.2.0/appimagelauncher-2.2.0-travis995.0f91801.x86_64.rpm
# Enable CachyOS addons EL10 fork repo
RUN dnf copr enable andersrh/kernel-cachyos-addons-el10 -y
# Enable CachyOS repositories # Enable CachyOS repositories
RUN dnf copr enable bieszczaders/kernel-cachyos -y RUN dnf copr enable bieszczaders/kernel-cachyos -y
RUN dnf install -y ${KERNEL} # Enable CachyOS addons EL10 fork repo
RUN dnf copr enable andersrh/kernel-cachyos-addons-el10 -y
RUN rpm -e --nodeps kernel kernel-core kernel-modules kernel-modules-core kernel-modules-extra RUN dnf install -y ${KERNEL} ${KERNEL}-devel-matched
RUN dnf install -y ${KERNEL}-devel ${KERNEL}-devel-matched RUN dnf remove -y kernel kernel-core kernel-modules kernel-modules-core kernel-modules-extra kernel-tools kernel-tools-libs
# Install Negativo17 Nvidia driver # Install Negativo17 Nvidia driver
RUN dnf install -y dkms-nvidia nvidia-driver nvidia-persistenced opencl-filesystem libva-nvidia-driver RUN dnf install -y dkms-nvidia nvidia-driver nvidia-persistenced opencl-filesystem libva-nvidia-driver
RUN dkms install nvidia/$(ls /usr/src/ | grep nvidia- | cut -d- -f2-) -k $(rpm -q --queryformat "%{VERSION}-%{RELEASE}.%{ARCH}\n" ${KERNEL})
# Install Nvidia X11 driver RUN dkms install nvidia/$(ls /usr/src/ | grep nvidia- | cut -d- -f2-) -k $(rpm -q --queryformat "%{VERSION}-%{RELEASE}.%{ARCH}\n" ${KERNEL})
RUN dnf install xorg-x11-nvidia --enablerepo=fc-nvidia -y
RUN dnf install -y waydroid scx-scheds RUN dnf install -y waydroid scx-scheds
@ -92,8 +72,10 @@ RUN dnf install firefox thunderbird -y
RUN rm -f /usr/lib64/libopenh264.so.2.4.1 /usr/lib64/libopenh264.so.7 RUN rm -f /usr/lib64/libopenh264.so.2.4.1 /usr/lib64/libopenh264.so.7
RUN rpm -Uvh --nodeps https://codecs.fedoraproject.org/openh264/42/x86_64/Packages/o/openh264-2.5.1-1.fc42.x86_64.rpm https://codecs.fedoraproject.org/openh264/42/x86_64/Packages/m/mozilla-openh264-2.5.1-1.fc42.x86_64.rpm RUN rpm -Uvh --nodeps https://codecs.fedoraproject.org/openh264/42/x86_64/Packages/o/openh264-2.5.1-1.fc42.x86_64.rpm https://codecs.fedoraproject.org/openh264/42/x86_64/Packages/m/mozilla-openh264-2.5.1-1.fc42.x86_64.rpm
RUN dnf install xorg-x11-xinit xkbcomp xinput xlibre-xserver-Xorg xlibre-xf86-input-libinput cage weston redshift -y
RUN dnf install ananicy-cpp cachyos-ananicy-rules cachyos-settings -y \ RUN dnf install ananicy-cpp cachyos-ananicy-rules cachyos-settings -y \
&& systemctl disable ananicy-cpp && systemctl enable ananicy-cpp
# Install VLC # Install VLC
RUN dnf install vlc vlc-plugins-freeworld vlc-plugin-pipewire -y RUN dnf install vlc vlc-plugins-freeworld vlc-plugin-pipewire -y
@ -102,29 +84,15 @@ RUN dnf install vlc vlc-plugins-freeworld vlc-plugin-pipewire -y
RUN dnf config-manager --add-repo https://brave-browser-rpm-release.s3.brave.com/brave-browser.repo -y RUN dnf config-manager --add-repo https://brave-browser-rpm-release.s3.brave.com/brave-browser.repo -y
RUN dnf install brave-browser -y RUN dnf install brave-browser -y
RUN dnf install rclone -y
RUN dnf install https://github.com/trapexit/mergerfs/releases/download/2.41.1/mergerfs-2.41.1-1.el10.x86_64.rpm -y
RUN dnf install -y virt-manager
RUN dnf install -y https://github.com/balena-io/etcher/releases/download/v2.1.6/balena-etcher-2.1.6-1.x86_64.rpm
RUN dnf install -y keepassxc
RUN systemctl enable docker RUN systemctl enable docker
RUN systemctl enable scx_loader
RUN echo 'kargs = ["mem_sleep_default=deep"]' > /usr/lib/bootc/kargs.d/10-mem-sleep.toml
RUN echo 'kargs = ["rd.driver.blacklist=nouveau", "nouveau.modeset=0"]' > /usr/lib/bootc/kargs.d/20-blacklist-nouveau.toml
RUN echo 'kargs = ["zswap.enabled=1", "zswap.shrinker_enabled=0", "zswap.compressor=zstd", "zswap.zpool=zsmalloc"]' > /usr/lib/bootc/kargs.d/30-zswap.toml
RUN printf '[connection]\nwifi.powersave=2\n' > /usr/lib/NetworkManager/conf.d/disable-wifi-powersave.conf
COPY etc /etc COPY etc /etc
COPY usr /usr COPY usr /usr
RUN systemctl enable waydroid-choose-intel-gpu.service RUN systemctl enable waydroid-choose-intel-gpu.service
# Disable SELinux RUN cd /usr/bin && wget https://raw.githubusercontent.com/CachyOS/CachyOS-Settings/refs/heads/master/usr/bin/kerver && chmod +x kerver
RUN sed -i "s/^SELINUX=.*$/SELINUX=permissive/g" /etc/sysconfig/selinux && sed -i "s/^SELINUX=.*$/SELINUX=permissive/g" /etc/selinux/config
RUN rm -rf /tmp/* /var/* && mkdir -p /var/tmp && chmod -R 1777 /var/tmp RUN rm -rf /tmp/* /var/* && mkdir -p /var/tmp && chmod -R 1777 /var/tmp && \
bootc container lint

View file

@ -0,0 +1,7 @@
Section "Device"
Identifier "Intel Graphics"
Driver "modesetting"
Option "ShadowFB" "false" # you don't need on recent hardware
Option "Atomic" "true" #only effective on Xlibre, or Xorg-git with a special patch
Option "TearFree" "false"
EndSection

View file

@ -1,31 +0,0 @@
Section "ServerLayout"
Identifier "layout"
Screen 0 "intel"
Inactive "nvidia"
Option "AllowNVIDIAGPUScreens"
EndSection
Section "Device"
Identifier "nvidia"
Driver "nvidia"
BusID "PCI:1:0:0"
EndSection
Section "Screen"
Identifier "nvidia"
Device "nvidia"
EndSection
Section "Device"
Identifier "intel"
Driver "modesetting"
BusID "PCI:0:2:0"
Option "ShadowFB" "false" # you don't need on recent hardware
Option "Atomic" "true" #only effective on Xlibre, or Xorg-git with a special patch
Option "TearFree" "false" # Compositor is being used so TearFree is not needed
EndSection
Section "Screen"
Identifier "intel"
Device "intel"
EndSection

View file

@ -1,35 +0,0 @@
[fc-nvidia]
name=negativo17 - Nvidia
baseurl=https://negativo17.org/repos/nvidia/fedora-44/$basearch/
enabled=0
skip_if_unavailable=1
gpgcheck=1
gpgkey=https://negativo17.org/repos/RPM-GPG-KEY-slaanesh
enabled_metadata=1
metadata_expire=6h
type=rpm-md
repo_gpgcheck=0
[fc-nvidia-source]
name=negativo17 - Nvidia - Source
baseurl=https://negativo17.org/repos/nvidia/fedora-44/SRPMS
enabled=0
skip_if_unavailable=1
gpgcheck=1
gpgkey=https://negativo17.org/repos/RPM-GPG-KEY-slaanesh
enabled_metadata=1
metadata_expire=6h
type=rpm-md
repo_gpgcheck=0
[fc-nvidia-debug]
name=negativo17 - Nvidia - Debug
baseurl=https://negativo17.org/repos/nvidia/fedora-44/$basearch.debug/
enabled=0
skip_if_unavailable=1
gpgcheck=1
gpgkey=https://negativo17.org/repos/RPM-GPG-KEY-slaanesh
enabled_metadata=1
metadata_expire=6h
type=rpm-md
repo_gpgcheck=0

View file

@ -1,12 +0,0 @@
#!/bin/sh
echo "--- ZSWAP STATUS IN RAM & DISK ---"
pages=$(sudo cat /sys/kernel/debug/zswap/stored_pages)
pool=$(sudo cat /sys/kernel/debug/zswap/pool_total_size)
wb_pages=$(sudo cat /sys/kernel/debug/zswap/written_back_pages)
inc_pages=$(sudo cat /sys/kernel/debug/zswap/stored_incompressible_pages)
echo "Data opsnappet i RAM (før komprimering): $((pages * 4 / 1024)) MB"
echo "Fysisk RAM brugt (efter komprimering): $((pool / 1024 / 1024)) MB"
echo "Skubbet fra RAM til disk (pool fuld): $((wb_pages * 4 / 1024)) MB"
echo "Sendt direkte til disk (ikke-komprimerbar): $((inc_pages * 4 / 1024)) MB"

View file

@ -0,0 +1,13 @@
# This field specifies the scheduler that will be started automatically when scx_loader starts (e.g., on boot).
default_sched = "scx_flash"
# This field specifies the mode which will be used when scx_loader starts (e.g., on boot).
#default_mode = "Auto"
# This "structure" allows configuring flags for each scheduler mode of particular scx scheduler
#[scheds.'scheduler']
#auto_mode = []
#gaming_mode = []
#lowlatency_mode = []
#powersave_mode = []
#server_mode = []